The Sandbox ecosystem has faced a serious challenge: attackers managed to exploit a vulnerability in the SAND token cross-chain bridge connecting the Base and BNB Smart Chain networks. As a result of the attack, unbacked tokens were issued in both networks, threatening the integrity of the asset.

Incident details and scale of damage

The analytics platform Blockaid recorded anomalous activity early in the morning. According to my data, the hacker intercepted control over the LayerZero delegate through the approveAndCall function, which allowed him to generate SAND without corresponding backing. The Sandbox team assessed the damage as minimal — less than 0.01% of the total token supply. However, the nominal volume of issued funds is impressive: about $49 billion in more than 400 transactions. It is important to emphasize that tokens in the Ethereum (ETH) and Polygon (POL) networks remained untouched, and user wallets were not compromised.

Team response and security measures

Developers promptly disabled the bridge between Base and BSC, blocking the ability to move and recover issued tokens. SAND locked in Ethereum, which serves as backing for all bridges, remained safe. In an official statement, the team emphasized that SAND in the affected networks is now isolated and unavailable for transfer or withdrawal.

Holders are strongly advised to refrain from any operations with SAND in these networks, as liquidity has been disrupted. To compensate losses for liquidity providers, a network snapshot from the moment before the attack is being prepared. A full report on what happened will be published later.

Market reaction and Korean exchanges

Korean crypto exchanges Bithumb and Upbit immediately suspended deposits and withdrawals of SAND, citing suspicions of a security breach and local legislation on protecting virtual asset owners. Notably, Upbit closed operations even with the SAND version on the Ethereum network, despite the team's assurances of its safety.

This incident fits into an alarming trend: according to DefiLlama, 17 hacks have occurred over the past month, and bridges have once again proven to be the industry's weakest link.

Expert opinion: Although the damage turned out to be insignificant, the very fact of the bridge hack via LayerZero demonstrates that even proven cross-chain protocols remain an attractive target. Investors should reconsider their strategies for storing assets on cross-chain infrastructure — diversification across networks does not always mean reduced risks.